Microsoft Threat Intelligence

Microsoft Threat Intelligence

@msftsecintel · Twitter ·

Microsoft Threat Intelligence is tracking reports of a suspected compromise of AsyncAPI's release pipeline, resulting in malicious packages published to the asyncapi npm namespace. Four packages (five versions) contain obfuscated malware. Combined, these packages see over 3 million downloads per week: - asyncapi/generator@3.3.1 - asyncapi/specs@6.11.2-alpha.1 - asyncapi/generator-helpers@1.1.1 - asyncapi/specs@6.11.2 - asyncapi/generator-components@0.7.1 The payload deploys a multi-stage RAT (characteristics overlapping publicly reported Miasma variants; attribution not confirmed) via hidden spawn, then downloads a second-stage payload from IPFS and persists as sync.js in user AppData. Microsoft Defender for Endpoint customers should act on these alerts: - Trojan:Script/Supychain.A To mitigate the issue: Pin to known-good versions, use lockfiles, and rotate any secrets exposed to affected CI runners.

Post media